Ransomware Group intelligence
Warlock
InactiveTrack Warlock with 78 published victims and 5 known leak locations in a single intelligence view.
Overview
Warlock is tracked by Breach House as a ransomware group with 78 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| File host (third party) | Third-party file host | Up checked 58m ago | drive.proton.me |
| Leak location 4 | Onion service | Down checked 58m ago | warlockhga5iw3t54ps5iytlilf7hlvxy7kwrkidspn4qoh64s4vsuyd.onion |
| Leak location 3 | Onion service | Down checked 59m ago | zfytizegsze6uiswodhbaalyy5rawaytv2nzyzdkt3susbewviqqh7yd.onion |
| Leak location 2 | Onion service | Down checked 59m ago | ocwjy4ynmpbbzhumh2ama2vl3bc77lf5auqf7nf4k45lbmzoep2rbyid.onion |
| Leak location 1 | Onion service | Down checked 59m ago | elqfbcx5nofwtqfookqml7ltx2g6q6tmddys6e25vgu3al2meim6cbqd.onion |
Top Activity Sectors (9)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Warlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: warlock executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: warlock modifies Windows Registry Run keys to establish persistence by injecting malicious startup entries.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: warlock disables antivirus tools by terminating security processes and modifying Windows Defender service configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: warlock deletes Volume Shadow Copies and backup folders via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: warlock accesses LSASS memory using a custom DLL injector to steal credentials for lateral movement.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: warlock scans network shares using net use commands to discover accessible victim directories for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: warlock exploits SMB shares to move laterally across networked systems within the victim environment.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: warlock exfiltrates stolen data via encrypted channels before deploying ransomware to maximize extortion leverage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: warlock encrypts victim files using a custom ransomware binary targeting documents and backups with AES encryption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: warlock executes system shutdown commands and service termination scripts to disrupt recovery operations.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (27)
▼Software Warlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
How to decrypt my data.txt
We are [Warlock Group], a professional hack organization. We regret to inform you that your systems have been successfully infiltrated by us, and your critical data, including sensitive files, databases, and customer information, has been encrypted. Additionally, we have securely backed up portions of your data to ensure the quality of our services. ====>What Happened? Your systems have been locked using our advanced encryption technology. You are currently unable to access critical files or continue normal business operations. We possess the decryption key and have backed up your data to ensure its safety. ====>If You Choose to Pay: Swift Recovery: We will provide the decryption key and detailed guidance to restore all your data within hours. Data Deletion: We guarantee the permanent deletion of any backed-up data in our possession after payment, protecting your privacy. Professional Support: Our technical team will assist you throughout the recovery process to ensure your systems are fully restored. Confidentiality: After the transaction, we will maintain strict confidentiality regarding this incident, ensuring no information is disclosed. ====>If You Refuse to Pay: Permanent Data Loss: Encrypted files will remain inaccessible, leading to business disruptions and potential financial losses. Data Exposure: The sensitive data we have backed up may be publicly released or sold to third parties, severely damaging your reputation and customer trust. Ongoing Attacks: Your systems may face further attacks, causing even greater harm. ====>How to Contact Us? Please reach out through the following secure channels for further instructions(When contacting us, please provide your decrypt ID): ###Contact 1: Your decrypt ID: [snip] Dark Web Link: http://warlock4fagqhnfuxtcmncfepe3jc33e33dmj2jsk64svxaerm5zhaqd.onion/touchus.html http://warlock5zli2g4nuvixkgyivpda4ktg6flx5lbtw3u6g5lidgxzjc6id.onion/touchus.html http://warlock6d4etw5gwwaakh6auh6cwkinhk2bx7bbldu4m5axlcwmbuuyd.onion/touchus.html http://warlockhga5iw3t54ps5iytlilf7hlvxy7kwrkidspn4qoh64s4vsuyd.onion/touchus.html http://warlockmdu64clit5pdwbp5hsd576vcjjigfwbtz5gtthmuy2fiqblad.onion/touchus.html http://warlockoact3ayzqwlnay27b633bku2gmpq34dxb43v3qriujfea4yyd.onion/touchus.html Your Chat Key: [snip] You can visit our website and log in with your chat key to contact us. Please note that this website is a dark web website and needs to be accessed using the Tor browser. You can visit the Tor Browser official website (https://www.torproject.org/) to download and install the Tor browser, and then visit our website. ###Contact 2: If you don't get a reply for a long time, you can also download qtox and add our ID to contact us Download:https://qtox.github.io/ Warlock qTox ID: 84490152E99B9EC4BCFE16080AFCFD6FDCD87512027E85DB318F7B3440982637FC2847F71685 Our team is available 24/7 to provide professional and courteous assistance throughout the payment and recovery process. We don't need a lot of money, it's very easy for you, you can earn money even if you lose it, but your data, reputation, and public image are irreversible, so contact us as soon as possible and prepare to pay is the first priority. Please contact us as soon as possible to avoid further consequences.
How_to_decrypt_my_data.txt
We are [Warlock Group], a professional hack organization. We regret to inform you that your systems have been successfully infiltrated by us, and your critical data, including sensitive files, databases, and customer information, has been encrypted. Additionally, we have securely backed up portions of your data to ensure the quality of our services. ====>What Happened? Your systems have been locked using our advanced encryption technology. You are currently unable to access critical files or continue normal business operations. We possess the decryption key and have backed up your data to ensure its safety. ====>If You Choose to Pay: Swift Recovery: We will provide the decryption key and detailed guidance to restore all your data within hours. Data Deletion: We guarantee the permanent deletion of any backed-up data in our possession after payment, protecting your privacy. Professional Support: Our technical team will assist you throughout the recovery process to ensure your systems are fully restored. Confidentiality: After the transaction, we will maintain strict confidentiality regarding this incident, ensuring no information is disclosed. ====>If You Refuse to Pay: Permanent Data Loss: Encrypted files will remain inaccessible, leading to business disruptions and potential financial losses. Data Exposure: The sensitive data we have backed up may be publicly released or sold to third parties, severely damaging your reputation and customer trust. Ongoing Attacks: Your systems may face further attacks, causing even greater harm. ====>How to Contact Us? Please reach out through the following secure channels for further instructions(When contacting us, please provide your decrypt ID): ###Contact 1: Your decrypt ID: [snip] Dark Web Link: http://zfytizegsze6uiswodhbaalyy5rawaytv2nzyzdkt3susbewviqqh7yd.onion/touchus.html Your Chat Key: [snip] You can visit our website and log in with your chat key to contact us. Please note that this website is a dark web website and needs to be accessed using the Tor browser. You can visit the Tor Browser official website (https://www.torproject.org/) to download and install the Tor browser, and then visit our website. ###Contact 2: If you don't get a reply for a long time, you can also download qtox and add our ID to contact us Download:https://qtox.github.io/ Warlock qTox ID: 84490152E99B9EC4BCFE16080AFCFD6FDCD87512027E85DB318F7B3440982637FC2847F71685 Our team is available 24/7 to provide professional and courteous assistance throughout the payment and recovery process. We don't need a lot of money, it's very easy for you, you can earn money even if you lose it, but your data, reputation, and public image are irreversible, so contact us as soon as possible and prepare to pay is the first priority. Please contact us as soon as possible to avoid further consequences.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (78)
Search, filter and paginate the victim timeline for Warlock. Showing 1–78 of 78.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | energogroup.net id23640 View details | Russian Federation | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | goldenline.com id23639 View details | Poland | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | bengineered.com.au id23638 View details | Australia | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | mnpease.ca id23637 View details | Canada | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | metro.local id23636 View details | Communication / Marketing | — | ||
|
No description provided. |
|||||
| Ransomware | cybervector.co.uk id23635 View details | United Kingdom | IT | — | |
|
No description provided. |
|||||
| Ransomware | fabrity.local id23634 View details | Poland | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | miltech.local id23633 View details | Iceland | IT | — | |
|
No description provided. |
|||||
| Ransomware | mytune.me id23632 View details | Malaysia | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | atg.cz id23631 View details | Czechia | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | tein.co.jp id23630 View details | Japan | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | bel.quadra.ru id23629 View details | Russian Federation | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | ippm.org id23628 View details | United Kingdom | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | sf.walltopia.com id23627 View details | United States | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | nartis.ru id23626 View details | Russian Federation | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | alphasys.bo id23625 View details | Bolivia, Plurinational State of | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | silanosn.local id23624 View details | Communication / Marketing | — | ||
|
No description provided. |
|||||
| Ransomware | siball.net id22547 View details | Russian Federation | Other | — | |
|
all data |
|||||
| Ransomware | chroma.com.tw id22425 View details | Taiwan, Province of China | Other | — | |
|
all data |
|||||
| Ransomware | ferus-smit.home id22424 View details | Netherlands | Other | — | |
|
all data |
|||||
| Ransomware | jubileelife.com id22423 View details | Pakistan | Other | — | |
|
all data |
|||||
| Ransomware | kmssa.net id22422 View details | Saudi Arabia | Other | — | |
|
all data |
|||||
| Ransomware | webville.net id22421 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | elssurveying.com id22420 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | medkar.com id22419 View details | Türkiye | Other | — | |
|
all data |
|||||
| Ransomware | okan.ru id22184 View details | Russian Federation | Finance / Legal / Insurance | — | |
|
finance data |
|||||
| Ransomware | mffood.com id22070 View details | Denmark | Agriculture / Food | — | |
|
300G data |
|||||
| Ransomware | gmpc.com id22069 View details | United States | Communication / Marketing | — | |
|
No description provided. |
|||||
| Ransomware | airfastindonesia.com id21933 View details | Indonesia | Other | — | |
|
all user data |
|||||
| Ransomware | infoniqa.com id21820 View details | Austria | Finance / Legal / Insurance | — | |
|
165g data, including internal documents, financial documents, employee information, CRM database, HR database, SaaS database |
|||||
| Ransomware | gmtaconline id21804 View details | Philippines | Other | — | |
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | woodboure id21803 View details | Other | — | ||
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | STRGOME id21802 View details | Other | — | ||
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | argeninta id21801 View details | Other | — | ||
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | houra id21800 View details | France | Other | — | |
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | houxt id21799 View details | United Kingdom | Other | — | |
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | getdomain id21798 View details | Denmark | Other | — | |
|
The data has been bought by other buyers (not victims) |
|||||
| Ransomware | kipl id21797 View details | India | Other | — | |
|
The customer has not paid, and there are no other buyers within the validity period, please enjoy your data |
|||||
| Ransomware | nszi id21796 View details | Croatia | Other | — | |
|
The customer has not paid, and there are no other buyers within the validity period, please enjoy your data |
|||||
| Ransomware | accsnet.com id21795 View details | Japan | Other | — | |
|
all data |
|||||
| Ransomware | advion.com id21794 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | mysecop.com id21793 View details | Other | — | ||
|
all data |
|||||
| Ransomware | atcmanufacturing id21792 View details | United States | Manufacturing / Engineering | — | |
|
all data |
|||||
| Ransomware | orange.com id21791 View details | France | Other | — | |
|
This is only a part of the files and file list. The full set of files needs to be purchased separately. |
|||||
| Ransomware | anthembio.com id21790 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | syspro.com id21789 View details | United States | Communication / Marketing | — | |
|
all data |
|||||
| Ransomware | brightwork.com id21788 View details | United States | Communication / Marketing | — | |
|
[AI generated] BrightWork.com is a project management software company that provides solutions for teams and organizations to manage and track their projects. It offers templates, reports, role-based dashboards, risk management and work automation tools. BrightWork.com is designed to be integrated with Microsoft SharePoint, thereby bringing clarity, control, and simplicity to project portfolios. |
|||||
| Ransomware | starsalliance.com id21787 View details | Other | — | ||
|
The data has been purchased by other buyers |
|||||
| Ransomware | sipecom.com id21786 View details | Ecuador | Other | — | |
|
all data |
|||||
| Ransomware | wytechnology.local id21785 View details | IT | — | ||
|
The data has been purchased by other buyers |
|||||
| Ransomware | webcids.com id21784 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | rougine-mfg.com id21783 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | magcpa.com id21782 View details | United States | Other | — | |
|
all data |
|||||
| Ransomware | wfd2027uae.ae id21781 View details | United Arab Emirates | Other | — | |
|
all data |
|||||
| Ransomware | tagorg.com id21780 View details | Jordan | Other | — | |
|
all data |
|||||
| Ransomware | hitachi-hta.com id21779 View details | Japan | Other | — | |
|
all data |
|||||
| Ransomware | primrose.com id21778 View details | United Kingdom | Communication / Marketing | — | |
|
all data |
|||||
| Ransomware | clearybuilding.us id21777 View details | United States | Construction / Real Estate | — | |
|
all data |
|||||
| Ransomware | colt.net id21776 View details | United Kingdom | Other | — | |
|
1 million documents,The full set of files needs to be purchased separately. |
|||||
| Ransomware | currimjee id20586 View details | Mauritius | Construction / Real Estate | — | |
|
[AI generated] Currimjee Group is a Mauritian company engaged in diversified sectors since 1890. Its sectors include Telecommunications, Media & IT, Energy, Real Estate, Tourism, Food & Beverages, Financial Services, Commerce & Manufacturing, and CSR. Currimjee's mission is to enhance the lives of the Mauritian population by consistently meeting their evolving needs and expectations. |
|||||
| Ransomware | via-optronics id20585 View details | Germany | Manufacturing / Engineering | — | |
|
[AI generated] Via Optronics is a global technology company that specializes in the production of interactive display systems and digital components. The company provides solutions such as enhanced displays, touch sensors, and optical bonding services. They mainly cater to consumer electronics, automotive, and industrial markets. With its headquarters in Germany, Via Optronics operates worldwide serving multiple industries. |
|||||
| Ransomware | iberol id20584 View details | Spain | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | eira-group id20583 View details | Finland | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | KMMP id20582 View details | Japan | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | nipponindiaim id20581 View details | India | Finance / Legal / Insurance | — | |
|
[AI generated] Nippon India Mutual Fund (NIMF), previously known as Reliance Mutual Fund, is one of the leading mutual fund companies in India. It is part of Nippon Life India Asset Management Limited, which is in turn a subsidiary of Nippon Life Insurance Company, Japan and Reliance Capital. The company offers a diverse range of investment solutions to individual and institutional investors. |
|||||
| Ransomware | unilever id20580 View details | Netherlands | Communication / Marketing | — | |
|
[AI generated] Unilever is a multinational corporation that sells branded consumer goods. Founded in 1929 and based in London, England and Rotterdam, Netherlands, their products range across food, beverages, cleaning agents, and personal care products. Unilever has products available in over 190 countries, and owns over 400 brands including Dove, Lipton, and Ben & Jerry's. |
|||||
| Ransomware | Ersar id20579 View details | Portugal | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | NCVOO id20578 View details | Bermuda | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | BTHK id20577 View details | Hong Kong | Other | ||
|
All data |
|||||
| Ransomware | lactanet id20576 View details | Canada | Agriculture / Food | — | |
|
[AI generated] Lactanet is an agricultural company that provides critical information and innovative solutions to dairy farmers to optimize the health and productivity of their herds. Formed through a merger of Canadian Dairy Network, Valacta, and CanWest DHI, it uses advanced genetics and dairy management software to improve herd and farm efficiency. |
|||||
| Ransomware | ssi-mi id20575 View details | Japan | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | dad id20574 View details | Other | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | astronika id20573 View details | Poland | Manufacturing / Engineering | — | |
|
[AI generated] Astronika is a Polish company that specializes in high-tech engineering solutions, with a particular focus on space technologies. Their main activities include research, design, and development of advanced mechanical systems. They undertake complex projects that require designing custom engineering solutions, such as components for satellites and other space mechanisms. Astronika works closely with scientific institutions and the space industry. |
|||||
| Ransomware | sras id20572 View details | Other | — | ||
|
[AI generated] N/A |
|||||
| Ransomware | icidesi id20571 View details | Türkiye | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | taos id20570 View details | United States | IT | — | |
|
[AI generated] Taos is a technology services and consulting firm that specializes in cloud, DevOps, and security solutions. Headquartered in San Jose, CA, they work with clients across various industries, including finance, healthcare, and technology. Their services range from strategic consulting to managing IT infrastructure. Their goal is to help businesses adopt new technologies and practices to improve their operations and deliver better results. |
|||||
| Ransomware | carducci id20569 View details | South Africa | Services | — | |
|
[AI generated] Carducci is an esteemed fashion brand hailing from Cape Town, South Africa. Founded in 1978, it specializes in sophisticated menswear, particularly business and casual wear, tailored suits, accessories, and footwear. The brand is renowned for its fine craftsmanship, refined textiles, and keen attention to detail. Carducci is part of the Seardel Group of Companies. |
|||||
| Ransomware | Arch-con id20568 View details | United States | Healthcare / Pharma | — | |
|
[AI generated] Arch-Con Corporation is a commercial construction company based in Houston, Texas. They work across various market sectors such as office, retail, healthcare, hospitality, industrial, and many more. Arch-Con offers construction management services at the risk of the constructor, providing guaranteed maximum prices to establish budget certainty. Their goal is to exceed client expectations using their experience, talents, and resources. |
|||||